31 Jul

DigiCert gives unlucky folks 24 hours to replace doomed certificates after code blunder

DigiCert has given some unlucky customers 24 hours to replace their SSL/TLS security certificates it previously issued them – due to a five-year-old blunder in

Author rabih
30 Jul

Delta Air Lines dials up Microsoft’s legal nemesis over CrowdStrike losses

Delta Air Lines lost hundreds of millions of dollars due to the CrowdStrike outage earlier this month – and it has hired a high-powered law

Author rabih
30 Jul

‘LockBit of phishing’ EvilProxy used in more than a million attacks every month

Insight The developers of EvilProxy – a phishing kit dubbed the “LockBit of phishing” – have produced guides on using legitimate Cloudflare services to disguise

Author rabih
30 Jul

Ransomware gangs are loving this dumb but deadly make-me-admin ESXi vulnerability

Do you have your VMware ESXi hypervisor joined to Active Directory? Well, the latest news from Microsoft serves as a reminder that you might not

Author rabih
30 Jul

Phishing targeting Polish SMBs continues via ModiLoader

ESET Research ESET researchers detected multiple, widespread phishing campaigns targeting SMBs in Poland during May 2024, distributing various malware families Jakub Kaloč 30 Jul 2024

Author rabih
30 Jul

Proofpoint phishing palaver plagues millions with ‘perfectly spoofed’ emails from IBM, Nike, Disney, others

A huge phishing campaign exploited a security blind-spot in Proofpoint’s email filtering systems to send an average of three million “perfectly spoofed” messages a day

Author rabih
30 Jul

Malaysia is working on an internet ‘kill switch’, says minister

Legislation for an internet “kill switch” will reach Malaysia’s Parliament in October, according to the country’s minister for Law and Institutional Reform. Minister Azalina Othman

Author rabih
29 Jul

Meta’s AI safety system defeated by the space bar

Meta’s machine-learning model for detecting prompt injection attacks – special prompts to make neural networks behave inappropriately – is itself vulnerable to, you guessed it,

Author rabih
29 Jul

Post-CrowdStrike, Microsoft to discourage use of kernel drivers by security tools

Updated Microsoft has vowed to reduce cybersecurity vendors’ reliance on kernel-mode code, which was at the heart of the CrowdStrike super-snafu this month. Redmond shared

Author rabih
29 Jul

US border cops really must get a warrant in NY before searching your phones, devices

US border agents must obtain a warrant, in New York at least, to search anyone’s phone and other electronic device when traveling in or out

Author rabih
29 Jul

Post-CrowdStrike, Microsoft to discourage use of kernel drivers by security software

Microsoft has admitted that its estimate of 8.5 million machines crashed by CrowdStrike’s faulty software update was based on incomplete data and vowed to reduce

Author rabih
29 Jul

Microsoft admits 8.5M CrowdStruck machines estimate was lowballed

Microsoft has admitted that its estimate of 8.5 million machines crashed by CrowdStrike’s faulty software update was almost certainly too low, and vowed to reduce

Author rabih
29 Jul

Intruders at HealthEquity rifled through storage, stole 4.3M people’s data

HealthEquity, a US fintech firm for the healthcare sector, admits that a “data security event” it discovered at the end of June hit the data

Author rabih
29 Jul

Google apologizes for breaking password manager for millions of Windows users with iffy Chrome update

Google celebrated Sysadmin Day last week by apologizing for breaking its password manager for millions of Windows users – just as many Windows admins were

Author rabih
29 Jul

Beware of fake AI tools masking very real malware threats

Generative AI (GenAI) is making waves across the world. Its popularity and widespread use has also attracted the attention of cybercriminals, leading to various cyberthreats.

Author rabih
29 Jul

Microsoft admits 8.5 million CrowdStruck machines estimate was lowballed

Microsoft has admitted that its estimate of 8.5 million machines crashed by CrowdStrike’s faulty software update was almost certainly too low, and vowed to reduce

Author rabih
29 Jul

China ponders creating a national ‘cyberspace ID’

Beijing may soon issue “cyberspace IDs” to its citizens, after floating a proposal for the scheme last Friday. Although the policy is only open for

Author rabih
29 Jul

Secure Boot useless on hundreds of PCs from major vendors after key leak

Infosec in brief Protecting computers’ BIOS and the boot process is essential for modern security – but knowing it’s important isn’t the same as actually

Author rabih
Load moreLoadingAll items loaded